logo

Linux 'io_uring' security blindspot allows stealthy rootkit attacks

ID: e7ec3d6f-bde8-5efb-a9bf-9af9222d599e

STIX ID: report--e7ec3d6f-bde8-5efb-a9bf-9af9222d599e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-04-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ARMO researchers disclosed that the Linux io_uring interface creates a significant runtime-security blindspot and released a proof-of-concept rootkit called "Curing" which abuses io_uring to execute remote commands and evade syscall-based detection; testing showed well-known runtime-security tools (e.g., Falco and default Tetragon) failed to detect the activity, prompting recommendations to adopt Kernel Runtime Security Instrumentation (KRSI)/eBPF mitigations and noting that Google disabled io_uring by default on Android/ChromeOS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.